CVE-2014-4696
 
Severity Score
5.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.
Múltiples vulnerabilidades de redirección abierta en el paquete Suricata anterior a 1.0.6 para pfSense hasta 2.1.4 permiten a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través del parámetro (1) referer en suricata_rules_flowbits.php o (2) returl en suricata_select_alias.php.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-06-28 CVE Reserved
- 2014-07-02 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pfsense.org/security/advisories/pfSense-SA-14_13.packages.asc | 2019-05-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgate Search vendor "Netgate" | Pfsense Search vendor "Netgate" for product "Pfsense" | <= 2.1.4 Search vendor "Netgate" for product "Pfsense" and version " <= 2.1.4" | - |
Affected
| ||||||
Netgate Search vendor "Netgate" | Pfsense Search vendor "Netgate" for product "Pfsense" | 2.1.3 Search vendor "Netgate" for product "Pfsense" and version "2.1.3" | - |
Affected
| ||||||
Pfsense Search vendor "Pfsense" | Suricata Package Search vendor "Pfsense" for product "Suricata Package" | <= 1.0.5 Search vendor "Pfsense" for product "Suricata Package" and version " <= 1.0.5" | - |
Affected
|